Skip to content

fix(release): ignore fork PRs in bump guard - #402

Open
luvs01 wants to merge 11 commits into
Devfrom
codex/investigate-and-fix-fork-pr-collision-vulnerability
Open

fix(release): ignore fork PRs in bump guard#402
luvs01 wants to merge 11 commits into
Devfrom
codex/investigate-and-fix-fork-pr-collision-vulnerability

Conversation

@luvs01

@luvs01 luvs01 commented Sep 1, 2026

Copy link
Copy Markdown
Owner

Motivation

  • Prevent fork-origin pull requests that reuse the predictable head branch codex/dev-version-${NEXT_VERSION} from suppressing the repository-owned bump PR.
  • Ensure the release-triggered workflow only treats an already-open PR as authoritative when its head belongs to the upstream repository.

Description

  • Update .github/workflows/dev-version-bump.yml to query gh pr list --json number,isCrossRepository and count only PRs with isCrossRepository == false, excluding fork PRs from the idempotency guard.
  • Keep the existing branch-resume logic that validates and reuses an existing bump branch when it is canonical and safe.
  • Add a regression test in tests/bump-dev-version.test.ts that asserts the workflow contains the --json number,isCrossRepository query and the select(.isCrossRepository == false) filter.

Testing

  • Ran the focused test bun test tests/bump-dev-version.test.ts, which passed the new assertions and most cases, with one environment-specific unwritable-directory test failing due to container filesystem semantics (known/expected in this environment).
  • Ran bun run privacy:scan which passed.
  • Ran git diff --check and bun run prepush checks where typecheck and gui lint passed but the repository-wide test run reported unrelated existing/time-sensitive failures, so full-suite CI remains the authoritative gate.

Codex Task

lidge-jun and others added 11 commits August 25, 2026 10:36
release: promote dev into main for v2.32.1
# Conflicts:
#	package.json
[WRONG BRANCH] merge dev into main for the v2.33.0 release
Promotes the dev integration line onto main. The resulting tree is byte-identical
to origin/dev, including package.json at 2.34.0.

The package.json conflict is resolved to dev's side, NOT to main's stale 2.33.0.
Earlier promotions (lidge-jun#2553, lidge-jun#2507) kept the target's version so the release bump
would land on its own "release: vX.Y.Z" commit. That is no longer legal: this very
delta adds tests/release-version-line.test.ts, which fails when the in-tree version
sits behind the highest release tag. With v2.34.0-preview.20260827 now published,
2.33.0 orders behind it, so a promotion carrying the stale line turns CI red on
every shard that runs the suite.

The consequence for the release step is that scripts/release.ts skips the bump
(release.ts:568, currentVersion === version), so v2.34.0 gets tagged on this merge
commit rather than on a separate release commit. The workflow creates the tag itself
after publishing and validates expected-sha against the checked-out commit, so the
tag still names exactly the audited tree.
[WRONG BRANCH] promote dev onto main for v2.34.0
[WRONG BRANCH] promote dev onto main for v2.35.0
[WRONG BRANCH] promote dev onto main for v2.36.0
[WRONG BRANCH] promote dev to main for the v2.37.0 release
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the bug Something isn't working label Sep 1, 2026
@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: 45f736ef-dae1-4dbb-b564-0da58bf535cf


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot changed the title fix(release): ignore fork PRs in bump guard [WRONG BRANCH] fix(release): ignore fork PRs in bump guard Sep 1, 2026
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

✅ READY

  • all PR quality gates passed.

Hygiene

Deterministic PR hygiene checks passed.

@github-actions
github-actions Bot marked this pull request as draft September 1, 2026 05:50

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 530c16b091

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

# `--head` matches only the branch name, including identically named fork
# branches. Count only pull requests whose head belongs to this repository;
# otherwise a fork can pre-open the predictable branch and suppress the bump.
open_prs="$(gh pr list --base dev --head "${branch}" --state open --json number,isCrossRepository --jq '[.[] | select(.isCrossRepository == false)] | length')"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Paginate the filtered pull-request lookup

When an upstream bump PR is already open and at least 30 same-named fork PRs precede it in gh pr list's results, the upstream PR is truncated before this jq filter runs: gh pr list --help documents a default --limit of 30. The filter then reports zero upstream PRs and falls through to gh pr create, which fails because that upstream PR already exists, turning a rerun into a red release job. Request sufficient results (or paginate) before filtering.

Useful? React with 👍 / 👎.

@luvs01 luvs01 changed the title [WRONG BRANCH] fix(release): ignore fork PRs in bump guard fix(release): ignore fork PRs in bump guard Sep 3, 2026
@luvs01
luvs01 changed the base branch from main to dev September 3, 2026 06:22
@github-actions
github-actions Bot marked this pull request as ready for review September 3, 2026 06:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aardvark bug Something isn't working codex

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants